VDB
Sign up
CRITICAL9.8

GHSA-j68w-pg49-f6vx

Symfony XML decoding attack vector through external entities

Quick fix

GHSA-j68w-pg49-f6vx — symfony/serializer: upgrade to the fixed version with the command below.

composer require symfony/serializer:^2.0.11

Details

The XMLEncoder component of Symfony 2.0.x fails to disable external entities when parsing XML. In the Symfony2 framework the XML class may be used to deserialize objects or as part of a client/server API. By using external entities it is possible to include arbitrary files from the file system.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/serializer
Introduced in: 2.0.0Fixed in: 2.0.11
Fixcomposer require symfony/serializer:^2.0.11

References